Safety vulnerability ID: 52879
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Barbican 12.0.2, 13.0.1 and 14.0.1 include a fix for CVE-2022-3100: This issue allows an access policy bypass via a query string when accessing the API.
https://github.com/openstack/barbican/commit/6112c302375bf3d4c27303d12beec52ce2a82a2b
Latest version: 19.0.0
OpenStack Secure Key Management
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. See CVE-2022-3100.
MISC:https://access.redhat.com/security/cve/CVE-2022-3100: https://access.redhat.com/security/cve/CVE-2022-3100
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application